Executive brief
Veeam ONE is a monitoring and management platform used to oversee backup and virtualization infrastructure. An unauthenticated attacker on the network can force the service account to authenticate via SMB, potentially leading to credential theft or lateral movement attacks. This vulnerability affects Veeam ONE version 13 and has been rated critical due to the ability to compromise service account credentials.
Technical details
This vulnerability allows an unauthenticated network attacker to coerce SMB authentication from Veeam ONE's service account, a form of credential exfiltration attack (similar to NTLM relay or responder-style attacks). The attack requires only network reachability to the affected service with no authentication or user interaction required. The vulnerable component accepts and processes SMB authentication requests from unauthenticated sources, allowing attackers to extract service account credentials or perform relay attacks. Affected versions are Veeam ONE 13.1.0.7034 and earlier 13.x builds; versions 12.x and earlier are not affected. Patches are available: Veeam ONE 13.1 Patch 0 (build 13.1.0.7233) and Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159).
Affected products
- Veeam ONE 13.1.0.7034 and earlier 13.x builds
Timeline
- 2026-08-26: disclosed
- 2026-08-25: patched: Veeam ONE 13.1 Patch 0 (build 13.1.0.7233) and Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159)
- 2026-08-25: other: Vulnerability reported through HackerOne